What Is a Keylogger?
A keylogger records keyboard input on a computer or mobile device. Attackers use keylogging to capture passwords, payment details, messages, search terms, and other information entered by a user. Monitoring can be implemented through malware, a malicious browser component, operating-system hooks, firmware, or a physical device.
Some keylogging is legitimate when it is disclosed and authorized for troubleshooting, accessibility, or monitored business use. It becomes a security threat when collection occurs without informed authorization or when an attacker abuses a legitimate monitoring capability.
Key Takeaways
- Keyloggers can be software-based, browser-based, kernel-level, mobile, or physical.
- Captured keystrokes often expose credentials before encryption protects the resulting network session.
- Detection requires endpoint, browser, mobile, identity, and physical-security context.
- Password changes should occur from a trusted device after the collection mechanism is removed.

How a Keylogger Works
A software keylogger may arrive through phishing, a Trojan, a malicious installer, an extension, or post-compromise tooling. It records input through application hooks, browser access, accessibility features, or lower-level system components.
Collected data is stored locally or sent to attacker infrastructure. More capable spyware may pair keystrokes with screenshots, clipboard content, window titles, form data, and session information to make the capture easier to interpret.
Common Types and Techniques
- User-mode and application-hook keyloggers
- Kernel, driver, and boot-level keyloggers
- Browser extensions and form-grabbing malware
- Hardware implants and malicious peripherals
Security and Business Risks
- Credential and financial theft
- Exposure of confidential communications
- Account takeover and session compromise
- Persistent surveillance of employees or executives

Warning Signs and Detection
Investigate unfamiliar processes, drivers, extensions, accessibility permissions, input hooks, scheduled tasks, startup items, and outbound traffic. Physical inspection matters for shared workstations, kiosks, and high-risk environments.
Prevention and Response
Use endpoint and mobile protection, restrict installation and administrator rights, manage browser extensions, patch systems, use phishing-resistant MFA, secure work areas, and allow only trusted peripherals. Rebuild a system when integrity cannot be established.
How SOCRadar Can Help
SOCRadar combines external asset visibility, threat intelligence, Dark Web monitoring, vulnerability context, and indicator enrichment to help teams identify exposure and investigate activity connected to keylogger.
Explore SOCRadar Dark Web Monitoring or request a demo to strengthen threat-informed prevention and investigation.
Frequently Asked Questions
Can a keylogger capture passwords?
Yes. A keylogger can record a password as it is typed, before the application hashes it or the network connection encrypts it.
Does an on-screen keyboard stop keylogging?
It may defeat a basic keyboard hook, but spyware can capture clicks, screenshots, clipboard data, forms, or accessibility events. It is not a complete defense.
What should a victim do first?
Disconnect the suspected device if active compromise is likely. Use a separate trusted device to reset important credentials and revoke sessions after the keylogger has been contained.
Are all keyloggers illegal?
No. Authorized and disclosed monitoring can have legitimate uses. Secret interception, unauthorized installation, or misuse of captured information can violate policy and law.
